downloadsetup.exe

Setup

Artua Vladislav

This is a WebPick installer that bundles (with very minimal user consent) a number of adware browser extensions which inject ads in the browser. The application downloadsetup.exe by Artua Vladislav has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the WebPick InstalleRex (Tarma) installer. The file has been seen being downloaded from premiumstorage.info. While running, it connects to the Internet address r1.stylezip.info on port 80 using the HTTP protocol.
Publisher:
Premium  (signed by Artua Vladislav)

Product:
Setup

Description:
Installer

Version:
2012.2.1.1348

MD5:
f773c875055ea11d9d1bd4fb2fc68a8f

SHA-1:
4db4ba0588228a6c5061ea164552a11babaa9d7f

SHA-256:
f8a8d40b16ece3197df2fa910a93d3df0dde3700d5ef1fc6b874935ed52d029f

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses Web-Pick's 'File Product', an Installer which wraps various products and downloads and installs it silently through the process, hosted on TusFiles.

Analysis date:
12/27/2024 7:29:50 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick.ArtuaVla.Installer (M)
16.7.1.12

File size:
250.1 KB (256,056 bytes)

Product version:
1.0

Copyright:
Copyright © 2010 Premium

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
WebPick InstalleRex (Tarma)

Common path:
C:\users\{user}\downloads\downloadsetup.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/15/2011 2:00:00 AM

Valid to:
3/15/2012 1:59:59 AM

Subject:
CN=Artua Vladislav, O=Artua Vladislav, STREET=haRav Dangur 22, L=Bnei Braq, S=Israel, PostalCode=51281, C=IL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
302242B18FB354EA399140DBBA22B786

File PE Metadata
Compilation timestamp:
1/6/2012 8:12:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:0xS9bljwkVieLKyF0fY6Fncxr/Ya0Ux6wfegXyr:0xcbBwkVikIfYiDa05wmyyr

Entry address:
0x149F

Entry point:
55, 8B, EC, 81, EC, 24, 06, 00, 00, 53, 56, 33, F6, 57, 66, 89, B5, E4, FB, FF, FF, 89, 75, F4, 89, 75, FC, FF, 15, 68, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 64, 30, 40, 00, 89, 45, F8, 68, 04, 01, 00, 00, 8D, 85, DC, F9, FF, FF, 50, 56, FF, 15, 60, 30, 40, 00, 85, C0, 75, 22, FF, 15, 5C, 30, 40, 00, 50, 68, A0, 32, 40, 00, E8, 8A, FB, FF, FF, 59, 59, C7, 05, 0C, 44, 40, 00, FF, 00, 00, 00, E9, F7, 01, 00, 00, 56, FF, 15, 58, 30, 40, 00, 8B, 48, 3C, 03, C8, 66, 81, 38, 4D, 5A, 0F, 85, BC, 01, 00, 00, 81...
 
[+]

Entropy:
7.9452

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file downloadsetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

Remove downloadsetup.exe - Powered by Reason Core Security